Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

381–390 of 473 posts

Re: Blocked by Cloudflare

#381
post #374
post #96

Earlier quoted context omitted.

I’m no Google fanboy but I wasn’t satisfied with this: > Chrome will happily collect as much private information about me and my browsing history and share them with select parties, as needed What information does Chrome provide in this scenario that Firefox doesn’t? It feels like backward logic: it worked in Chrome therefore it must be because Chrome gave extra info. In reality it could be a whole bunch of things, s…

https://privacytests.org/ shows some good data what each browser lets through/exposes for websites.

Caveat: (default settings)

I harden my Firefox installations, and therefore this website comparison isn't useful.

Re: Blocked by Cloudflare

#382

Earlier quoted context omitted.

Cloudflare's Privacy Pass may help here: https://privacypass.github.io/ It should significantly reduce the amount of CAPTCHAs you see in a way that's not terrible for privacy. For Safari, you can enable Private Access Tokens: https://blog.cloudflare.com/how-to-enable-private-access-tok... Both of these mechanisms are similar to Google's web DRM proposal in that they rely on external issuers to generate tokens, but un…

Pay us with your information to make your problem go away.

What information do you think this addon gathers? Cloudflare already receives every bit of information this addon collects when you visit a Cloudflare website without it.

Re: Blocked by Cloudflare

#383

Earlier quoted context omitted.

I don't praise 1.1.1.1 because it's just a DNS server. My firewall's set to redirect all DNS queries there. It works fine. Could've used 8.8.8.8 instead, but I trust CloudFlare slightly more.

There’s aeverql other providers none of whom are as large as cloudflare - including quad-9 and opendns, and of course your own ISP

Yeah, I could've used any one of them, before 1.1.1.1 I usually used Google.

Re: Blocked by Cloudflare

#384

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

I've seen this behavior on sites with CSPs that'd break the challenge, They somehow get loaded from cache and cause failed requests.

This somehow even persisted into the browser's incognito mode, and I had to use an entirely different browser. This wasn't on a small unknown site either.

(It looks like pinned CSPs are a dead standard, but did anyone implement it?)

Re: Blocked by Cloudflare

#385
post #354

Earlier quoted context omitted.

7f3bfdf6bee5b9ea here is one. I'm not on my PC so i used a privacy enchanted fork of Mobile Chrome. Enabled WebGL, WebRTC and WASM. Disabled all the fingerprint resistant features i could easily (the only thing messing with your systems could be the HTTP Referrer or Timezone) Perhaps its a DNS-level issue? Does cloudflare use any google related APIs to provide the integrity check?

> Perhaps its a DNS-level issue? I run dnscrypt-proxy and I have seen CloudFlare protected sites reject me based on that. I haven't been able to pinpoint which upstream resolver provider causes it as I have it set to automatically cycle through and it's intermittent enough that I haven't bothered getting to the bottom of it (ie. doesn't happen for several weeks and then happens for 15 minutes or so before resolving).…

I was using my PiHole and switched to NextDNS to check. Didnt work.

Re: Blocked by Cloudflare

#387

Earlier quoted context omitted.

Pay us with your information to make your problem go away.

What information do you think this addon gathers? Cloudflare already receives every bit of information this addon collects when you visit a Cloudflare website without it.

un-CF'ed websites? im speculating however

Re: Blocked by Cloudflare

#388
post #80

The amount of times Cloudflare is making me sit through their 15 to 30 second "checking your connection" page is insane. For people going through life with ADHD such as myself, the impact of all these delays and disruptions throughout the day can be severe. Despite being properly medicated this measure is absolutely debilitating and makes for a dreadful and very taxing online experience.

That's typically deployed on sites under heavy DDOS attacks. Nobody wants for their users to see that, they are forced to.

No need to simplify so much that only false dichotomies remain. My brain might be wired up differently but its capacity for nuance and reason is fully intact :)

No one is forcing the website owners to sign up with Cloudflare to enable this service with these aggressive configurations, and yet I understand why they would even just pre-emptively. It's cheap and effective, there's no denying that.

It is Cloudflare Inc. (66,59USD, +23.57USD/54.79% YTD), however, that architected the solution, markets it as a service, and controls it as a core part of their (i.e. everyone's) internet architecture.

As a serviceprovider they could be better at informing their customers of these unintentional side-effects and how they impact otherwise innocent visitors, but whose mental disorders/impairments cause them to be flagged for and having to undergo additional verification steps disproportionately more than others, likely due to some atypical behavioural patterns they show and their often adjusted hardsoftware setups producing an unconventional signature.

Some modifications to the system could probably be made on the architectural level too. We can get people in wheelchairs to the top of the empire state building, surely we can also find a solution that allows us to enjoy the benefits of these protective measures without wrecking the web's inclusivity and accessibility this much every time the measures need to be stepped up.

Am I asking for too much, what do you think?

Re: Blocked by Cloudflare

#389
post #381
post #374

Earlier quoted context omitted.

https://privacytests.org/ shows some good data what each browser lets through/exposes for websites.

Caveat: (default settings) I harden my Firefox installations, and therefore this website comparison isn't useful.

It does have Librewolf and Mullvad listed, which are hardened Firefox forks. But its still not your exact scenario, my bad :)

Re: Blocked by Cloudflare

#390

Earlier quoted context omitted.

They block and/or slowdown over 20% of the internet How can you not see that as anything but an "attack"?

Man in the middle attack typically implies an unwanted third party, which in this case is not true since Cloudfare is explicitly and voluntarily trusted by the host server. It wouldn't be all that different if the web server had the browserintegrity checks developed themselves.

>an unwanted third party

This is precisely what Cloudflare is doing to end users - causing problems like OP (and myriad others) experience by slowing down and/or blocking major chunks of the internet

Post reply on HN